CIA-2 - Information Gathering, Analysis, and Evaluation - Section B.6

Determine whether there is a difference between evaluation criteria and existing conditions, and evaluate the significance of each finding, including root causes and potential effects.

Compare existing conditions against the evaluation criteria established during planning to identify gaps, then identify the root causes of any deviation and its potential effects on the organisation. Appraise the factors that establish how significant a finding is, so that findings are prioritised by real impact rather than by how easily they were observed.

Finding significanceRoot cause analysisEvaluation criteria

Practice question for this objective

Free sampleInformation Gathering, Analysis, and Evaluationhard

An auditor at Calder Health assesses overtime pay and compares actual payments against the criterion that all overtime must be pre-approved by a department head. Payroll records show 30 percent of overtime lacked pre-approval, but interviews reveal the approval workflow was disabled for two months during a system upgrade, with a manager reviewing hours afterwards. How should the auditor interpret this difference between criteria and condition?

  • ATreat the 30 percent gap as a control failure of equal significance across the whole period under review.
  • BDismiss the difference because a manager reviewed the hours afterwards, providing an adequate substitute control.
  • CReport the raw deviation against the criterion without adjusting for the disabled workflow, to stay objective.
  • DWeigh the deviation against its root cause and the compensating review to judge the residual risk and true effect. Correct
Evaluating a finding means weighing the raw deviation against its root cause and any compensating controls to judge the residual effect. A gap against criteria is not automatically significant. The auditor must factor in why the condition arose and whether compensating controls limited the effect, so the reported residual risk reflects reality rather than the surface deviation rate.

Why A is wrong: Tempting because the headline rate looks uniform, but a compensating manual review and a time-bounded cause change the real effect, so equal weighting overstates it.

Why B is wrong: Tempting since a compensating control exists, but after-the-fact review is weaker than pre-approval, so dismissing the gap ignores the residual risk it leaves.

Why C is wrong: Tempting as it seems neutral, but ignoring a known cause and a compensating control misstates significance; objectivity requires evaluating the effect, not just the deviation.

Why D is correct: Correct because significance depends on cause and effect together; the timed outage and the manual review reduce, though do not remove, the residual risk the finding represents.

See more CIA-2 practice questions, answers explained.

More in this domain

Back to all Information Gathering, Analysis, and Evaluation objectives, or the CIA-2 cert hub.

Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. Original, blueprint-aligned practice material only.